
Nepali Date Converter Security & Risk Analysis
wordpress.org/plugins/nepali-date-converterConvert English dates to Nepali and vice versa, including WordPress post dates. Includes widgets, shortcodes, and custom functions.
Is Nepali Date Converter Safe to Use in 2026?
Generally Safe
Score 99/100Nepali Date Converter has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'nepali-date-converter' v3.0.5 plugin exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, which are largely implemented correctly. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. Furthermore, the plugin utilizes nonce checks for its AJAX handlers, a crucial security measure. However, the analysis reveals a concerning lack of capability checks on its entry points. While the static analysis did not find immediate exploitable vulnerabilities, the absence of capability checks means that any user, regardless of their WordPress role, could potentially trigger the plugin's AJAX handlers, which could lead to unintended actions or information disclosure if not properly secured within the handler's logic itself.
The plugin's vulnerability history shows a single known CVE in the past, which is now patched. This suggests a willingness to address security issues, but the presence of even one past vulnerability warrants continued vigilance. The common vulnerability type being Cross-site Scripting is a reminder that input validation and output sanitization are critical, and while the current output escaping is high, the past history means this area should be continuously monitored. Overall, the plugin has good foundational security practices, but the missing capability checks on entry points represent a significant area for improvement to further harden its security.
Key Concerns
- Missing capability checks on entry points
- Past CVE: Improper Neutralization of Input During Web Page Generation ('Cross-si
Nepali Date Converter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Nepali Date Converter <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
Nepali Date Converter Release Timeline
Nepali Date Converter Code Analysis
Output Escaping
Nepali Date Converter Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Nepali Date Converter Maintenance & Trust
Maintenance Signals
Community Trust
Nepali Date Converter Alternatives
Nepali Date Utilities
nepali-date-utilities
"Nepali Date Utilities" plugin converts English to Nepali dates, offering post dates and today’s date via shortcode for easy display on sites.
Nyasro Nepali Date Converter
nyasro-nepali-date-converter
Nyasro Nepali Date Converter allows to convert A.D. (English Date) to B.S. (Nepali Date) and Vice Versa.
CHP Nepali Date Converter
chp-nepali-date-converter
CHP Nepali Date Converter plugin is developed in order to provide dates conversion from English to Nepali dates and Vice Versa.
Nepali Date Converter Developer Profile
5 plugins · 92K total installs
How We Detect Nepali Date Converter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nepali-date-converter/assets/css/script.css/wp-content/plugins/nepali-date-converter/assets/js/widget.js/wp-content/plugins/nepali-date-converter/assets/js/widget.jsnepali-date-converter/assets/css/script.css?ver=nepali-date-converter/assets/js/widget.js?ver=HTML / DOM Fingerprints
widget_nepali_date_converterdata-nepali_date_langdata-nep_to_eng_button_textdata-eng_to_nep_button_textdata-disable_ndc_convert_nep_to_engdata-disable_ndc_convert_eng_to_nepdata-nepali_date_converter_result_formatndc_widget_data